Report for IP: 80.102.218.207

Threat LevelCRITICAL72/1002 rule types across 2 attack categories
2 incidents on record · 2 rule types · active attack detected · persistent 8-day campaign · last seen 24d ago
PTR 207.pool80-102-218.dynamic.orange.es
Org / ASN AS12479 Orange Espagne SA
Country 🇪🇸 Spain
City Frigiliana, Andalusia
Timezone Europe/Madrid

Attack Analysis

🇪🇸 Spain · Frigiliana · 12479
SSH: Login Attempt — Non-Existent User
This IP attempted to authenticate via SSH using a username that does not exist on the system. This is characteristic of automated credential-stuffing attacks cycling through common username wordlists (admin, root, ubuntu, pi, etc.).
Suricata IDS Alert
Suricata intrusion detection flagged this IP for malicious network behaviour — including port scanning, exploit attempts, botnet activity, or known attack signatures. The specific signature is shown in the report list below.

Reports (2)

Date Severity Description
7 Jul 2026 - 18:36 medium IDS: Suricata alert — Honeypot: probe to closed SSH port 22
30 Jun 2026 - 05:03 high SSH: Login attempt using non-existent user